← Back to overview
How strong is your password, really?
Most password advice stops at “use a mix of letters, numbers and symbols.” This tool goes further: test a password or generate one, see its real strength and how long it would actually take to crack under three realistic attack scenarios, all directly in your browser. Nothing you type is ever sent anywhere.
⏱️ How long would it take to crack?
What makes a password strong — in short
Length beats complexity. A long passphrase made of random words resists every technique below far better than a short, "clever" 8-character password.
💥
Brute force
Trying every possible combination, character by character. A modern GPU tests billions per second offline — an 8-character password falls in hours; add 8 more and it takes millions of years.
📖
Dictionary attack
Trying real words, names and known leaked passwords first, with common substitutions (a→@, o→0). "P@ssw0rd2024" looks complex — it's one of the first guesses.
🎭
Social engineering
No cracking at all: a convincing email, call or fake login page tricks you into typing your password directly. The strongest password can't defend against this — only vigilance and a password manager can.
The one habit that matters most: a different password for every service, generated (not remembered) and stored in a password manager. That way, one leaked site never puts your other accounts at risk.
Go further with a second factor: even the strongest password can be phished or leaked, so add a second factor wherever it's offered. An authenticator app (TOTP) is a solid baseline; a physical security key (FIDO2/U2F) goes further still, since it can't be phished or read out over the phone the way a one-time code can. Any option beats SMS codes alone, which can be intercepted or SIM-swapped. What matters is having a second factor at all, on every account that allows it, starting with email and your password manager.